Hi ash2l,
If you download and install Splunk, you get the Enterprise Trail license http://docs.splunk.com/Documentation/Splunk/latest/Admin/TypesofSplunklicenses#Compare_license_features which is a fully featured license valid for 60 days http://docs.splunk.com/Documentation/Splunk/latest/Admin/TypesofSplunklicenses#Enterprise_trial_license
You might got confused with the free license http://docs.splunk.com/Documentation/Splunk/latest/Admin/TypesofSplunklicenses#Free_license which has the following features disabled:
Multiple user accounts and role-based access controls
Distributed search
Forwarding in TCP/HTTP formats (you can forward data to other Splunk software instances, but not to non-Splunk software instances)
Deployment management (including for clients)
Alerting/monitoring
Authentication and user management, including native authentication, LDAP, and scripted authentication.
There is no login. The command line or browser can access and control all aspects of Splunk software with no user/password prompt.
You cannot add more roles or create user accounts.
Searches are run against all public indexes, 'index=*' and restrictions on search such as user quotas, maximum per-search time ranges, search filters are not supported.
The capability system is disabled, all capabilities are enabled for all users accessing Splunk software.
Hope that helps and good luck with the exam ...
cheers, MuS
... View more